<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" stage-count="1" star-print="no-star-print"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>116 S1457 IS: Sharing Urgent, Potentially Problematic Locations that Yield Communications Hazards in American Internet Networks Act of 2019</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2019-05-14</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>116th CONGRESS</congress><session>1st Session</session><legis-num>S. 1457</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20190514">May 14, 2019</action-date><action-desc><sponsor name-id="S396">Mrs. Blackburn</sponsor> (for herself and <cosponsor name-id="S287">Mr. Cornyn</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To provide for interagency coordination on risk mitigation in the communications equipment and
			 services marketplace and the supply chain thereof, and for other purposes.</official-title></form>
	<legis-body>
 <section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Sharing Urgent, Potentially Problematic Locations that Yield Communications Hazards in American Internet Networks Act of 2019</short-title></quote> or the <quote><short-title>SUPPLY CHAIN Act of 2019</short-title></quote>.</text>
		</section><section id="ida4d87ede8a41460db5f6fcb5c1398d48"><enum>2.</enum><header>Interagency coordination on risk mitigation in the communications equipment and services
			 marketplace and the supply chain
			 thereof</header>
 <subsection id="id3127363f010b406ba23ed6422bef92b4"><enum>(a)</enum><header>Definitions</header><text>In this section:</text> <paragraph id="idb15b86ea1b4c459495f94e875d004950"><enum>(1)</enum><header>Appropriate committees of Congress</header><text>The term <term>appropriate committees of Congress</term> means—</text>
 <subparagraph id="id28bce3e929cb42169997d452e9a49ee2"><enum>(A)</enum><text>the Committee on Commerce, Science, and Transportation, the Committee on Foreign Relations, the Committee on Armed Services, the Committee on the Judiciary, the Committee on Homeland Security and Governmental Affairs, and the Select Committee on Intelligence of the Senate; and</text>
 </subparagraph><subparagraph id="idc8355ea06d634772b74e8fa7cc88020e"><enum>(B)</enum><text>the Committee on Energy and Commerce, the Committee on Foreign Affairs, the Committee on Armed Services, the Committee on the Judiciary, the Committee on Homeland Security, and the Permanent Select Committee on Intelligence of the House of Representatives.</text>
 </subparagraph></paragraph><paragraph id="idfc182f0311874abba883142e6560c282"><enum>(2)</enum><header>Appropriate Federal entity</header><text>The term <term>appropriate Federal entity</term> means—</text> <subparagraph id="id7655dbe4a5f84504922c2fa39961a509"><enum>(A)</enum><text>the Department of Defense;</text>
 </subparagraph><subparagraph id="idB40AAC6333F84EE6A2096848D9B33857"><enum>(B)</enum><text>the Department of Energy;</text> </subparagraph><subparagraph id="idFE62CCEA294C42088F6EFCA05C263957"><enum>(C)</enum><text>the Department of Homeland Security;</text>
 </subparagraph><subparagraph id="id765FC2C9CC47460FA2627BE52835EEEF"><enum>(D)</enum><text>the Department of Justice;</text> </subparagraph><subparagraph id="id5DBF8CA25A934A1ABB824FC46C25B2F4"><enum>(E)</enum><text>the Department of Transportation;</text>
 </subparagraph><subparagraph id="id74234EF4BA9E4A41B16269EA0924B18D"><enum>(F)</enum><text>the Department of the Treasury; and</text> </subparagraph><subparagraph id="id9D24135B935B49EE9B42134AA2F1B29B"><enum>(G)</enum><text>the Office of the Director of National Intelligence.</text>
 </subparagraph></paragraph><paragraph id="id0c6937588fdf477cbf0cf11a45c69c82"><enum>(3)</enum><header>Classified information</header><text>The term <term>classified information</term> means any information or material that has been determined by the Federal Government pursuant to an Executive order, statute, or regulation, to require protection against unauthorized disclosure for reasons of national security.</text>
 </paragraph><paragraph id="id037e27dae91647a180894e1802341d6e"><enum>(4)</enum><header>Communications equipment and services</header><text>The term <term>communications equipment and services</term> includes any hardware, software, or other product or service primarily intended to fulfill or enable the function of information processing and communications by electronic means, including transmission and display, including over the internet.</text>
 </paragraph><paragraph id="id303da47689144d02a198a2e55c9a636c"><enum>(5)</enum><header>Risk</header><text>The term <term>risk</term> means any aspect or property of the components of communications equipment and services or the associated supply chain that may be used to gain unauthorized access to a communications network, disrupt a communications network, disrupt the manufacture of communications equipment, disrupt consensus-driven industry standards for communications equipment and services, or otherwise harm a communications network or the users of the network, including gaining unauthorized access to data or redirecting data.</text>
 </paragraph><paragraph id="idF0A9F084005C4F85B2EB69A8A6D3AAE9"><enum>(6)</enum><header>Secretary</header><text>The term <term>Secretary</term> means the Secretary of Commerce.</text> </paragraph><paragraph id="id6dc9c69016c944e8b23aa14415515b56"><enum>(7)</enum><header>Supply chain</header><text>The term <term>supply chain</term>, with respect to communications equipment and services—</text>
 <subparagraph id="id616d3dbbb687412ea98a5f513a600b3b"><enum>(A)</enum><text>means the network of persons and activities from source to delivery of the equipment and services; and</text>
 </subparagraph><subparagraph id="id0872a3c0efb84440818c915c1437ef9e"><enum>(B)</enum><text>includes—</text> <clause id="id7b81c77f0ebf48f1bab90de3aab09d3b"><enum>(i)</enum><text>vendors, suppliers, and providers of the equipment and services; and</text>
 </clause><clause id="id1ae242e96fc841798349674e4877ebbf"><enum>(ii)</enum><text>persons who manufacture, assemble, develop, or test the equipment and services.</text> </clause></subparagraph></paragraph></subsection><subsection id="id23c35ed9dbef4c60b3dec373ac6593fe"><enum>(b)</enum><header>Ongoing review</header><text>Consistent with the protection of classified information, the Secretary shall, in coordination with the head of each appropriate Federal entity, conduct an ongoing review of risks to the communications equipment and services marketplace and the supply chain thereof.</text>
			</subsection><subsection id="id7d4a36a25d0f4009b12c4d92e3ed96b7"><enum>(c)</enum><header>Long-Term scenario and strategic planning</header>
 <paragraph id="idccc7f602fcbb40c48284c4698d3382f6"><enum>(1)</enum><header>Development, issuance, and implementation of procedures</header><text>Not later than 180 days after the date of enactment of this section, consistent with the protection of classified information, the Secretary, in coordination with the head of each appropriate Federal entity, shall—</text>
 <subparagraph id="id782204e390d44b259f63f799adae0512"><enum>(A)</enum><text>develop and issue procedures to regularly facilitate—</text> <clause id="idd172196e75f4438b8c9b39d93a707d18"><enum>(i)</enum><text>long-term scenario and strategic planning with private entities that have appropriate security clearances to review classified information about risks, including by—</text>
 <subclause id="id420d0d0cd8b04134818555e362a35891"><enum>(I)</enum><text>assessing the severity of risks posed to the marketplace of individual components of communications equipment and services and the supply chain thereof;</text>
 </subclause><subclause id="id6630903a6e724fe5a5532e87fe3b846c"><enum>(II)</enum><text>identifying counterfeit communications equipment and services in the marketplace;</text> </subclause><subclause id="id4808182c9b5c4ed09cdd2f195942a247"><enum>(III)</enum><text>assessing the ability of foreign governments or third parties to exploit the marketplace in a manner that raises risks;</text>
 </subclause><subclause id="id7ca5c0e5cffc46e6a195aa1408b50ab2"><enum>(IV)</enum><text>identifying—</text> <item id="id26C403CD66EA492A87ED26F81D2FE73A"><enum>(aa)</enum><text>emerging risks and long-term trends in the marketplace of individual components or standards of communications equipment and services and the supply chain thereof; and</text>
 </item><item id="id6EEB6F1DBE2B473DAD8A9236AE11C1F6"><enum>(bb)</enum><text>strategies to mitigate risks described in item (aa); and</text> </item></subclause><subclause id="ida67abeca4a74471c95f136c55cc00032"><enum>(V)</enum><text>analyzing opportunities for asymmetric advantage;</text>
 </subclause></clause><clause id="idedaf2462c56941a7b1177fff4485dae4"><enum>(ii)</enum><text>the—</text> <subclause id="id5221417364D44AC3A388BEEAFB38871A"><enum>(I)</enum><text>preparation of unclassified information that raises awareness of risks, including, as appropriate, unclassified versions of any information shared under clause (i); and</text>
 </subclause><subclause id="id1FBB6A6DA6A24AFCA6FBF4545EFB9EE6"><enum>(II)</enum><text>dissemination by the Secretary of the unclassified information described in subclause (I) to private entities that do not have appropriate security clearances; and</text>
 </subclause></clause><clause id="id1749c4f418e049118d296c3f6075d147"><enum>(iii)</enum><text>the voluntary sharing from private entities to the Secretary of information about risks to the marketplace; and</text>
 </clause></subparagraph><subparagraph id="id9907c22fa21840a38173a38f828789bc"><enum>(B)</enum><text>carry out the procedures developed and issued under subparagraph (A).</text> </subparagraph></paragraph><paragraph id="id27beda7ea0cf450e8e4e68c86c8acf69"><enum>(2)</enum><header>Manner of presentation</header><text>The information shared with private entities under paragraph (1)(A)(i) shall be presented in a manner that identifies, assesses, and prioritizes risks, the mitigation of risks, and opportunities for asymmetric advantage.</text>
				</paragraph><paragraph id="idd5f6a7d04a374831a0a5d09e1ddf3a26"><enum>(3)</enum><header>Information shared with or provided to the Federal Government</header>
 <subparagraph id="ide8ef087cf35340ffb83df3db9c0bdb8a"><enum>(A)</enum><header>No waiver of privilege or protection</header><text>The provision of information to the Federal Government by a private entity under clause (i) or (iii) of paragraph (1)(A) shall not constitute a waiver of any applicable privilege or protection provided by law, including trade secret protection.</text>
 </subparagraph><subparagraph id="idcef9ccf17b354dfea3a6e976296db38d"><enum>(B)</enum><header>Proprietary information</header><text>Information provided to the Federal Government by a private entity under clause (i) or (iii) of paragraph (1)(A) shall be considered the commercial, financial, and proprietary information of the private entity.</text>
 </subparagraph><subparagraph id="id7e9d6e423ad54671b290e431f90fa48b"><enum>(C)</enum><header>Exemption from disclosure under FOIA</header><text>Information provided to the Federal Government by a private entity under clause (i) or (iii) of paragraph (1)(A) shall be exempt from disclosure under section 552(b)(3) of title 5, United States Code.</text>
 </subparagraph><subparagraph id="id059261287a5a4eb996967d55aa103307"><enum>(D)</enum><header>Exemption from Federal regulatory authority</header><text>Information provided to the Federal Government by a private entity under clause (i) or (iii) of paragraph (1)(A) shall not be used by any Federal entity to regulate, including through an enforcement action, the lawful activities of the private entity.</text>
 </subparagraph><subparagraph id="ida37745d0f9714490bfce9778dae04cb7"><enum>(E)</enum><header>Protection from liability</header><text>No cause of action shall lie or be maintained in any court against a private entity, and such action shall be promptly dismissed, if the action is related to or arises out of the provision of information to the Federal Government by the private entity under clause (i) or (iii) of paragraph (1)(A).</text>
					</subparagraph></paragraph></subsection><subsection id="iddc1fb375b40d45c8ae3a6bdd31923d32"><enum>(d)</enum><header>Report to Congress</header>
 <paragraph id="idc64917b590a042a38cd783ce6edc2788"><enum>(1)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this section, and biennially thereafter, the Secretary, in coordination with the head of each appropriate Federal entity, shall submit to the appropriate committees of Congress a report on the implementation of this section.</text>
 </paragraph><paragraph id="idd7aa847c431d4a809345006f91c065fe"><enum>(2)</enum><header>Contents</header><text>The report required under paragraph (1) shall—</text> <subparagraph id="id41c701dd12a34599823d1e1bf1355857"><enum>(A)</enum><text>include any recommendations that the Secretary, in collaboration with the heads of the appropriate Federal entities, may have for improvements or modifications to the procedures developed and issued under this section;</text>
 </subparagraph><subparagraph id="id55129a12276f4af4904ff982c149fec4"><enum>(B)</enum><text>evaluate the effectiveness of the procedures developed and issued under subsection (c)(1)(A);</text> </subparagraph><subparagraph id="id61e9a1b56ce248be957ef9dc53baa813"><enum>(C)</enum><text>identify processes and procedures that improve the ability of private entities and the Federal Government to adapt to emerging risks to the marketplace;</text>
 </subparagraph><subparagraph id="id1e017aa511f04b3d8fdc91bd6660b892"><enum>(D)</enum><text>provide technical guidance on procurement of communications equipment and services offered by private entities in order to mitigate vulnerabilities;</text>
 </subparagraph><subparagraph id="id2680b305842c4c9b9260ad9c7fb1c20c"><enum>(E)</enum><text>include recommendations to streamline the provision of security clearances for relevant private sector actors; and</text>
 </subparagraph><subparagraph id="idC17A9699EAF045BEA9DC1055172DA39A"><enum>(F)</enum><text>assess coordination between the heads of the appropriate Federal entities, including by identifying distinct competencies and jurisdictions of each appropriate Federal entity.</text>
 </subparagraph></paragraph><paragraph id="idc46991d935e8479e9d54a3e3b540597d"><enum>(3)</enum><header>Form of reports</header><text>Each report submitted under paragraph (1) shall be in unclassified form, but may include a classified annex.</text>
 </paragraph></subsection><subsection id="idDC3B7AC563D64251BACFC8A6F8CBE479"><enum>(e)</enum><header>Rule of construction</header><text>Nothing in this section shall be construed to authorize the Secretary or the head of any other Federal agency to issue new regulations.</text></subsection></section></legis-body></bill>


